← Back to search

modelcontextprotocol/inspector

modelcontextprotocol NOASSERTION 9,813 stars Scanned 4d ago

C
60.8 / 100

Versions

0.21.2-hotfix-3latest
Apr 14, 2026
0.21.1
Feb 27, 2026
0.21.0
Feb 24, 2026
0.20.0
Feb 6, 2026
0.19.0-hotfix
Jan 23, 2026
+ show 45 moreshow less
0.18.0
Dec 16, 2025
0.17.5
Dec 4, 2025
0.17.4
Nov 26, 2025
0.17.3
Nov 25, 2025
0.17.2
Oct 22, 2025
0.17.1
Oct 13, 2025
0.17.0
Oct 1, 2025
0.16.8
Sep 17, 2025
0.16.7
Sep 12, 2025
0.16.6
Sep 3, 2025
0.16.5
Aug 18, 2025
0.16.4
Aug 14, 2025
0.16.3
Aug 9, 2025
0.16.2
Jul 25, 2025
0.16.1
Jul 10, 2025
0.16.0
Jul 8, 2025
0.15.0
Jun 26, 2025
0.14.3
Jun 18, 2025
0.14.2
Jun 14, 2025
0.14.1
Jun 13, 2025
0.14.0
Jun 4, 2025
0.13.0
May 21, 2025
0.12.0
May 9, 2025
0.11.0-amended
Apr 30, 2025
0.10.2
Apr 17, 2025
0.9.0
Apr 14, 2025
0.8.2
Apr 7, 2025
0.8.1-hotfix
Apr 3, 2025
0.8.0
Apr 2, 2025
0.7.0
Mar 25, 2025
0.6.0
Mar 11, 2025
0.5.1
Mar 5, 2025
0.4.1
Feb 12, 2025
0.4.0
Feb 5, 2025
0.3.0
Dec 5, 2024
0.2.7
Nov 29, 2024
0.2.6
Nov 27, 2024
0.2.5
Nov 27, 2024
0.2.4
Nov 27, 2024
0.2.3
Nov 26, 2024
0.2.2
Nov 25, 2024
0.2.1
Nov 25, 2024
0.2.0
Nov 21, 2024
0.1.0
Nov 11, 2024
0.0.1
Oct 28, 2024
1.0.0latest
first seen May 20, 2026
PermissionsTool SafetyAuthAnnotationsCode QualityStabilitySpecVuln HistoryAuthorTransparencyCommunity

Tools 5

test-tool
annotations: none low

Test tool

definitely-not-a-real-tool
annotations: none low

get_temp
annotations: none low

echo
annotations: none low

weather_app
annotations: none low

Permissions 4

network medium
Server uses network capabilities via: fetch(), http, net
filesystem low
Server uses filesystem capabilities via: fs, fs sync ops, fs/promises
shell high
Server uses shell capabilities via: child_process, execSync(), spawn(), spawnSync()
env_vars low
Server uses env_vars capabilities via: process.env

Scan Findings 92

medium
No build provenance detected (SLSA L0) slsa_assessor · 90%
medium
Vulnerable dependency: undici@8.5.0 (GHSA-8xcm-r25x-g524) dependency_analyzer · 95%
medium
Vulnerable dependency: undici@8.5.0 (GHSA-jr45-8vmc-qm54) dependency_analyzer · 95%
medium
Vulnerable dependency: undici@8.5.0 (GHSA-m8rv-5g2x-5cg5) dependency_analyzer · 95%
medium
Vulnerable dependency: undici@8.5.0 (GHSA-v3r7-h72x-cjcm) dependency_analyzer · 95%
medium
Buffer.from base64 in modelcontextprotocol-inspector-86d5f58/test-servers/src/test-server-oauth.ts:464 entropy_analyzer · 75%
info
package.json metadata manifest_parser · 100%
info
Tool: test-tool manifest_parser · 90%
info
Tool: definitely-not-a-real-tool manifest_parser · 90%
info
Tool: get_temp manifest_parser · 90%
info
Tool: echo manifest_parser · 90%
info
Tool: weather_app manifest_parser · 90%
info
Transport: streamable-http manifest_parser · 80%
info
Required env vars (36) manifest_parser · 80%
medium
Hardcoded OAuth client ID in modelcontextprotocol-inspector-86d5f58/clients/web/src/test/integration/mcp/ema-mock-servers.ts oauth_scope_analyzer · 80%
medium
Hardcoded OAuth client ID in modelcontextprotocol-inspector-86d5f58/clients/web/src/test/core/mcp/inspectorClient-satisfied-recovery-connect.test.ts oauth_scope_analyzer · 80%
medium
Hardcoded OAuth client ID in modelcontextprotocol-inspector-86d5f58/clients/web/src/test/core/mcp/node/servers.test.ts oauth_scope_analyzer · 80%
high
High-risk OAuth scope: admin oauth_scope_analyzer · 80%
info
Sandbox failed to start for output poisoning scan output_poisoning · 100%
medium
Permission: network access detected permission_analyzer · 90%
low
Permission: filesystem access detected permission_analyzer · 90%
high
Permission: shell access detected permission_analyzer · 95%
low
Permission: env_vars access detected permission_analyzer · 90%
info
SBOM generated: 945 components sbom_generator · 100%
medium
Suspicious package name: react-icons dependency_analyzer · 60%
medium
Suspicious package name: react-markdown dependency_analyzer · 60%
medium
Vulnerable dependency: ajv@8.17.1 (GHSA-2g4f-4pwh-qvx6) dependency_analyzer · 95%
low
Tool 'test-tool' has no annotations annotation_checker · 100%
low
Tool 'definitely-not-a-real-tool' has no annotations annotation_checker · 100%
low
Tool 'get_temp' has no annotations annotation_checker · 100%
low
Tool 'echo' has no annotations annotation_checker · 100%
low
Tool 'weather_app' has no annotations annotation_checker · 100%
high
Hardcoded OAuth client secret in modelcontextprotocol-inspector-86d5f58/core/auth/secret-fields.ts auth_checker · 95%
high
Hardcoded OAuth client secret in modelcontextprotocol-inspector-86d5f58/clients/web/src/utils/maskSecrets.test.ts auth_checker · 95%
high
Hardcoded OAuth client ID in modelcontextprotocol-inspector-86d5f58/clients/web/src/test/integration/mcp/ema-mock-servers.ts auth_checker · 85%
high
Hardcoded OAuth client secret in modelcontextprotocol-inspector-86d5f58/clients/web/src/test/integration/mcp/ema-mock-servers.ts auth_checker · 95%
high
Hardcoded OAuth client secret in modelcontextprotocol-inspector-86d5f58/clients/web/src/test/integration/mcp/inspectorClient-oauth.test.ts auth_checker · 95%
high
Hardcoded OAuth client secret in modelcontextprotocol-inspector-86d5f58/clients/web/src/test/integration/mcp/remote/servers-route.test.ts auth_checker · 95%
high
Hardcoded OAuth client secret in modelcontextprotocol-inspector-86d5f58/clients/web/src/test/integration/mcp/remote/client-store-route.test.ts auth_checker · 95%
high
Hardcoded OAuth client secret in modelcontextprotocol-inspector-86d5f58/clients/web/src/test/integration/auth/node/storage.test.ts auth_checker · 95%
high
Hardcoded OAuth client secret in modelcontextprotocol-inspector-86d5f58/clients/web/src/test/core/mcp/serverList.test.ts auth_checker · 95%
high
Hardcoded OAuth client ID in modelcontextprotocol-inspector-86d5f58/clients/web/src/test/core/mcp/inspectorClient-satisfied-recovery-connect.test.ts auth_checker · 85%
high
Hardcoded OAuth client secret in modelcontextprotocol-inspector-86d5f58/clients/web/src/test/core/mcp/oauthManager.test.ts auth_checker · 95%
high
Hardcoded OAuth client secret in modelcontextprotocol-inspector-86d5f58/clients/web/src/test/core/auth/storage-browser.test.ts auth_checker · 95%
high
Hardcoded OAuth client secret in modelcontextprotocol-inspector-86d5f58/clients/web/src/test/core/client/runner.test.ts auth_checker · 95%
high
Hardcoded OAuth client ID in modelcontextprotocol-inspector-86d5f58/clients/web/src/test/core/mcp/node/servers.test.ts auth_checker · 85%
high
Hardcoded OAuth client secret in modelcontextprotocol-inspector-86d5f58/clients/web/src/test/core/auth/ema/idpOidc.test.ts auth_checker · 95%
high
Hardcoded OAuth client secret in modelcontextprotocol-inspector-86d5f58/clients/web/src/test/core/auth/ema/tokenEndpoint.test.ts auth_checker · 95%
high
Hardcoded OAuth client secret in modelcontextprotocol-inspector-86d5f58/clients/cli/__tests__/oauth-runner.test.ts auth_checker · 95%
info
Sandbox failed to start for behavioral verification behavioral_verifier · 100%
medium
Excessive dependency count: 66 direct dependencies dependency_analyzer · 90%
medium
Suspicious package name: react-dom dependency_analyzer · 60%
medium
Vulnerable dependency: hono@4.12.18 (GHSA-2gcr-mfcq-wcc3) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.12.18 (GHSA-3hrh-pfw6-9m5x) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.12.18 (GHSA-54fx-42gc-7vw4) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.12.18 (GHSA-79qm-7rj5-m7r9) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.12.18 (GHSA-88fw-hqm2-52qc) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.12.18 (GHSA-8j4g-w8fx-2239) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.12.18 (GHSA-f23p-vx2j-j53r) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.12.18 (GHSA-f577-qrjj-4474) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.12.18 (GHSA-hvrm-45r6-mjfj) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.12.18 (GHSA-j6c9-x7qj-28xf) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.12.18 (GHSA-rv63-4mwf-qqc2) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.12.18 (GHSA-w62v-xxxg-mg59) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.12.18 (GHSA-wgpf-jwqj-8h8p) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.12.18 (GHSA-wwfh-h76j-fc44) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.12.18 (GHSA-xgm2-5f3f-mvvc) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.12.18 (GHSA-xrhx-7g5j-rcj5) dependency_analyzer · 95%
medium
Vulnerable dependency: undici@8.5.0 (GHSA-4cwx-7wf7-3272) dependency_analyzer · 95%
info
Transport: streamable-http manifest_parser · 80%
info
Required env vars (11) manifest_parser · 80%
medium
Permission: network access detected permission_analyzer · 70%
low
Permission: filesystem access detected permission_analyzer · 90%
high
Permission: shell access detected permission_analyzer · 95%
low
Permission: env_vars access detected permission_analyzer · 90%
medium
Excessive dependency count: 51 direct dependencies dependency_analyzer · 90%
medium
Suspicious package name: react-dom dependency_analyzer · 60%
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.25.2 (GHSA-345p-7cg4-v4c7) dependency_analyzer · 95%
medium
Vulnerable dependency: ws@8.18.0 (GHSA-58qx-3vcg-4xpx) dependency_analyzer · 95%
medium
Vulnerable dependency: express-rate-limit@8.2.1 (GHSA-46wh-pxpv-q5gq) dependency_analyzer · 95%
medium
Vulnerable dependency: ajv@6.12.6 (GHSA-2g4f-4pwh-qvx6) dependency_analyzer · 95%
medium
Vulnerable dependency: postcss@8.5.6 (GHSA-qx2v-qp2m-jg93) dependency_analyzer · 95%
medium
Vulnerable dependency: vite@7.1.11 (GHSA-4w7w-66w2-5vf9) dependency_analyzer · 95%
medium
Vulnerable dependency: vite@7.1.11 (GHSA-p9ff-h696-f583) dependency_analyzer · 95%
medium
Vulnerable dependency: vite@7.1.11 (GHSA-v2wj-q39q-566r) dependency_analyzer · 95%
info
SLSA Build Level 3 detected slsa_assessor · 85%
info
Scanner output_poisoning failed output_poisoning · 50%
info
Scanner behavioral_verifier failed behavioral_verifier · 50%
info
SBOM generated: 938 components sbom_generator · 100%
info
MITRE ATLAS technique coverage summary atlas_annotator · 100%
info
ATLAS: Adversarial ML Supply Chain (AML.T0043) atlas_annotator · 100%
info
package.json metadata manifest_parser · 100%